Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/publish.azurepipelineextension.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
permissions:
contents: read
name: Publish to Azure Pipeline Extension
on:
workflow_dispatch:
Expand Down
12 changes: 0 additions & 12 deletions .github/workflows/publish.crates.rust.sdk.yml

This file was deleted.

13 changes: 0 additions & 13 deletions .github/workflows/publish.maven.java.storage.gcp.kms.yml

This file was deleted.

74 changes: 74 additions & 0 deletions .github/workflows/publish.maven.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
permissions:
contents: read
name: Publish to Maven
on:
workflow_dispatch:

jobs:
get-version:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ./sdk/java/core
outputs:
version: ${{ steps.extract-version.outputs.version }}
steps:
- uses: actions/checkout@v3
- name: Extract version from build.gradle.kts
id: extract-version
run: |
VERSION=$(grep -Po 'version\s*=\s*"\K[^"]*' build.gradle.kts || echo "0.0.0-unknown")
echo "Version retrieved: $VERSION"
echo "version=$VERSION" >> $GITHUB_OUTPUT

generate-and-upload-sbom:
Comment thread Fixed
needs: get-version
uses: ./.github/workflows/reusable.sbom.workflow.yml
with:
working-directory: ./sdk/java/core
project-name: keeper-secrets-manager-java
project-type: java
project-version: ${{ needs.get-version.outputs.version }}
sbom-format: spdx-json
additional-labels: ksm,sdk,java,security
secrets:
MANIFEST_TOKEN: ${{ secrets.MANIFEST_TOKEN }}

publish-java:
needs: generate-and-upload-sbom
environment: prod
runs-on: ubuntu-latest

defaults:
run:
working-directory: ./sdk/java/core

steps:
- name: Get the source code
uses: actions/checkout@v3

- name: Set up Java 11
uses: actions/setup-java@v2
with:
java-version: '11'
distribution: 'adopt'

- name: Validate Gradle wrapper
uses: gradle/wrapper-validation-action@e6e38bacfdf1a337459f332974bb2327a31aaf4b

- name: Retrieve secrets from KSM
id: ksmsecrets
uses: Keeper-Security/ksm-action@v1
with:
keeper-secret-config: ${{ secrets.KSM_ARTIFACT_JAVA_APP_CONFIG }}
secrets: |
zOVOneDczofWFlfizjC5Qw/file/90A46CD1-private-key.asc > file:/tmp/signing_secret_key_ring_file.asc
zOVOneDczofWFlfizjC5Qw/custom_field/signing.keyId > env:SIGNING_KEY_ID
zOVOneDczofWFlfizjC5Qw/custom_field/signing.password > env:SIGNING_PASSWORD
zOVOneDczofWFlfizjC5Qw/custom_field/ossrhUsername > env:OSSRH_USERNAME
zOVOneDczofWFlfizjC5Qw/custom_field/ossrhPassword > env:OSSRH_PASSWORD

- name: Publish package
env:
SIGNING_SECRET_KEY_RING_FILE: /tmp/signing_secret_key_ring_file.asc
run: gradle publishMavenJavaPublicationToSonatypeRepository
68 changes: 1 addition & 67 deletions .github/workflows/publish.npm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,73 +3,7 @@ on:
workflow_dispatch:

jobs:
generate-sbom:
runs-on: ubuntu-latest
steps:
- name: Get the source code
uses: actions/checkout@v3

- name: Install Syft
run: |
echo "Installing Syft v1.18.1..."
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b /tmp/bin v1.18.1
echo "/tmp/bin" >> $GITHUB_PATH

- name: Install Manifest CLI
run: |
echo "Installing Manifest CLI v0.18.3..."
curl -sSfL https://raw.githubusercontent.com/manifest-cyber/cli/main/install.sh | sh -s -- -b /tmp/bin v0.18.3

- name: Create Syft configuration
run: |
cat > syft-config.yaml << 'EOF'
package:
search:
scope: all-layers
cataloger:
enabled: true
java:
enabled: false
python:
enabled: false
nodejs:
enabled: true
EOF

- name: Generate and upload SBOM
env:
MANIFEST_API_KEY: ${{ secrets.MANIFEST_TOKEN }}
run: |
JAVASCRIPT_SDK_DIR="./sdk/javascript"

# Get version from package.json
echo "Detecting JavaScript SDK version..."
if [ -f "${JAVASCRIPT_SDK_DIR}/packages/core/package.json" ]; then
VERSION=$(grep -o '"version": "[^"]*"' "${JAVASCRIPT_SDK_DIR}/packages/core/package.json" | cut -d'"' -f4)
echo "Detected version: ${VERSION}"
else
VERSION="1.0.0"
echo "Could not detect version, using default: ${VERSION}"
fi

echo "Generating SBOM with Manifest CLI..."
/tmp/bin/manifest sbom "${JAVASCRIPT_SDK_DIR}" \
--generator=syft \
--name=keeper-secrets-manager-js-sdk \
--version=${VERSION} \
--output=spdx-json \
--file=js-sdk-sbom.json \
--api-key=${MANIFEST_API_KEY} \
--publish=true \
--asset-label=application,sbom-generated,nodejs \
--generator-config=syft-config.yaml

echo "SBOM generated and uploaded successfully: js-sdk-sbom.json"
echo "---------- SBOM Preview (first 20 lines) ----------"
head -n 20 js-sdk-sbom.json

publish-npm:
needs: generate-sbom
environment: prod
runs-on: ubuntu-latest

Expand All @@ -93,4 +27,4 @@ jobs:
run: npm install

- name: Publish package
run: npm publish
run: npm publish
44 changes: 0 additions & 44 deletions .github/workflows/publish.pypi.sdk.storage.gcp.kms.yml

This file was deleted.

47 changes: 0 additions & 47 deletions .github/workflows/publish.pypi.sdk.storage.oracle.kms.yml

This file was deleted.

6 changes: 3 additions & 3 deletions .github/workflows/publish.pypi.sdk.storage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,17 +11,17 @@ jobs:

defaults:
run:
working-directory: ./sdk/python/storage/keeper_secrets_manager_storages
working-directory: ./sdk/python/storage

steps:
- name: Get the source code
uses: actions/checkout@v3


- name: Set up Python 3.12
- name: Set up Python 3.9
uses: actions/setup-python@v4
with:
python-version: 3.12
python-version: 3.9

- name: Retrieve secrets from KSM
id: ksmsecrets
Expand Down
42 changes: 40 additions & 2 deletions .github/workflows/reusable.sbom.workflow.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,41 @@
name: Reusable SBOM Generation

on:
workflow_call:
inputs:
working-directory:
description: 'Directory containing the project files'
required: true
type: string
project-name:
description: 'Name of the project for SBOM identification'
required: true
type: string
project-type:
description: 'Type of project (python, dotnet, nodejs)'
required: true
type: string
project-version:
description: 'Version of the project (optional, will try to detect if not provided)'
required: false
type: string
default: ''
sbom-format:
description: 'Format for SBOM output (spdx-json, cyclonedx-json)'
required: false
type: string
default: 'spdx-json'
additional-labels:
description: 'Additional labels for SBOM categorization'
required: false
type: string
default: ''
secrets:
MANIFEST_TOKEN:
description: 'Token for Manifest.io authentication'
required: true
name: Reusable SBOM Generation

on:
workflow_call:
inputs:
Expand Down Expand Up @@ -36,10 +72,13 @@ on:
required: true

jobs:
generate-sbom:
name: Generate SBOM
generate-sbom:
name: Generate SBOM
runs-on: ubuntu-latest


steps:
- name: Checkout repository
uses: actions/checkout@v3
Expand Down Expand Up @@ -351,7 +390,6 @@ jobs:
- name: Generate and publish SBOM
env:
PROJECT_VERSION: ${{ inputs.project-version != '' && inputs.project-version || steps.detect-version.outputs.version }}
MANIFEST_TOKEN: ${{ secrets.MANIFEST_TOKEN }}
SYFT_PACKAGE_SEARCH_UNINDEXED_ARCHIVES: "true"
SYFT_PACKAGE_SEARCH_INDEXED_ARCHIVES: "true"
SYFT_SCOPE: "all-layers"
Expand Down Expand Up @@ -465,7 +503,7 @@ jobs:
--name=${{ inputs.project-name }} \
--version=${PROJECT_VERSION} \
--output=${{ inputs.sbom-format }} \
--api-key=${MANIFEST_TOKEN} \
--api-key=${{ secrets.MANIFEST_TOKEN }} \
--publish=true \
--label=${FINAL_LABELS}

Expand Down
Loading